TeamTNT Taps Docker to Unleash Sliver Malware in Major Cloud Assault

Amber | Attack Report
Download PDF

TeamTNT, a notorious hacking group, is preparing a large-scale campaign targeting cloud-native environments, marking a return to their original methods. The group is leveraging exposed Docker daemons as a critical entry point, allowing them to infiltrate and exploit vulnerable cloud infrastructures. Through these entry points, TeamTNT aims to deploy the Sliver malware, and a cyber worm alongside cryptominers, using compromised servers and Docker Hub as pillars of their malicious ecosystem. This approach highlights the group’s adaptability and emphasizes the critical need for vigilant cloud security to thwart resource hijacking and malware spread.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox

Cyber Horizons 2025

What Last Year’s Attacks Reveal About Today’s Risks

Watch the Webinar on-demand and get a FREE copy of our Cyber Horizons 2025 report.

Our Speakers
Speaker 1

Prateek Bhajanka Global Field CISO & Former Gartner Analyst Hive Pro Inc.

Speaker 2

Ankit Mani Manager Threat Intel HiveForce Labs

Speaker 3

Sreevani Tonipe Senior Threat Researcher HiveForce Labs